|
|
Log in / Subscribe / Register

wordpress: multiple vulnerabilities

Package(s):wordpress CVE #(s):CVE-2016-7168 CVE-2016-7169
Created:September 9, 2016 Updated:September 30, 2016
Description:

From the arch Linux advisory:

CVE-2016-7168 (cross-site scripting) A cross-site scripting vulnerability via an image filename, reported by SumOfPwm researcher Cengiz Han Sahin.

CVE-2016-7169 (directory traversal) A directory traversal vulnerability in the upgrade package uploader, reported by Dominik Schilling from the Wordpress security team.

Alerts:
Debian DSA-3681-1 wordpress 2016-09-29
Arch Linux ASA-201609-32 wordpress 2016-09-30
Debian-LTS DLA-633-1 wordpress 2016-09-22
Arch Linux ASA-201609-4 wordpress 2016-09-09

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds